S3C2 Summit 2023-02: Industry Secure Supply Chain Summit
Trevor Dunlap, Yasemin Acar, Michel Cucker, William Enck and, Alexandros Kapravelos, Christian Kastner, Laurie Williams

TL;DR
The paper summarizes a 2023 industry summit where practitioners shared experiences and challenges in securing software supply chains, emphasizing collaboration and practical insights into SBOMs, dependencies, and vulnerabilities.
Contribution
It provides a detailed summary of industry discussions on software supply chain security challenges and collaborative approaches from a diverse set of practitioners.
Findings
Shared practical challenges in securing supply chains
Highlighted importance of SBOMs and dependency management
Emphasized need for industry collaboration
Abstract
Recent years have shown increased cyber attacks targeting less secure elements in the software supply chain and causing fatal damage to businesses and organizations. Past well-known examples of software supply chain attacks are the SolarWinds or log4j incidents that have affected thousands of customers and businesses. The US government and industry are equally interested in enhancing software supply chain security. On February 22, 2023, researchers from the NSF-supported Secure Software Supply Chain Center (S3C2) conducted a Secure Software Supply Chain Summit with a diverse set of 17 practitioners from 15 companies. The goal of the Summit is to enable sharing between industry practitioners having practical experiences and challenges with software supply chain security and helping to form new collaborations. We conducted six-panel discussions based upon open-ended questions regarding…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Advanced Malware Detection Techniques · Cybercrime and Law Enforcement Studies
